Arcade File Downloads Support Forum
Email
Confirm email
Articles File Help Startup DB Tips Service DB Hijack This! Analyzer

 

HijackThis automated log analyzer! Get your logs analyzed INSTANTLY!

Key:

  • "Y" - Normally leave to run at start-up
  • "N" - Not required - typically infrequently used tasks that can be started manually if necessary
  • "U" - User's choice - depends whether a user deems it necessary
  • "X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
  • "?" - Unknown
Startup Name Process Name Details
X Service Controller service.exe"Added by the PREVERT TROJAN!"
X Service Defender [random filename]"Added by a variant of the ZLOB TROJAN! See here"
X Service Drivers Compt.exe"Added by the RBOT-ZJ WORM!"
X Service Drivers msnpg.exe"Added by the RBOT.BMD WORM!"
X Service Drivers PC.EXE"Added by the SDBOT-WK WORM!"
X Service Drivers abl.exe"Added by the SDBOT-YX WORM!"
X Service Drivers MSNMEssenger.exe"Added by a variant of the RBOT WORM!"
X Service Host svchost.exe"Added by the TORVEL WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder"
X Service Host [filename].exe"Added by the TORVEL.B WORM!"
X Service Host spoolxx.exe"Added by the TORVEL WORM!"
X Service Host svchost.exe"Added by the DAOSER-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Services{C922CCC4-CF61-4589-A0D1-828160704853} subfolder"
X Service Host svchost.exe"Added by the DAOSER-C TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a Services[random] subfolder"
X Service Host Driver svchost.exe"Added by the HITON TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder"
X Service Host Process spoolsvc.exe"Added by the GAOBOT.GEN!POLY WORM!"
N Service Manager sqlmangr.exeSQL Server Service Manager - provides tray access to SQL server the server agent and MSDTC. Available via Start → Programs
X Service Manager dxsound.exe"Added by the PROXY-GRIC TROJAN!"
X Service Manager SERVICEMGR.EXE"Added by the PASSMAIL-D VIRUS!"
X service manager service.exe"Added by the DONBOMB.A TROJAN!"
X Service Monitor msnfilen.exe"Added by the RBOT-ALE WORM!"
X Service Monitor javams32.exe"Added by the DELF-NK TROJAN!"
X Service Monitor javams64.exe"Added by the SDBOT-AFO WORM!"
X Service Monitor msnserve.exe"Added by the SPYBOT.YQW WORM!"
X Service Monitor WinOcx.exe"Added by the RBOT-AQJ WORM!"
X Service Monitor csnss.exe"Added by the RBOT.EEH WORM!"
X Service Monitor filen.exe"Added by a variant of the RBOT WORM!"
X Service Pack [various filenames]"Added by the LERPA-A WORM! Note - the file name will be one of the following common.exe common.pif common.scr Sexo.exe Sexo.jpg.pif ini_file__.pif load_me__.tmp msfile.pif system_load_.pif or zipped.rar.pif"
X Service Pack 1 [random filename]"Added by the VXGAME.Z TROJAN! Note - the filename is random - see the link. Typical examples are vexg6ame4.exe vexga3me2.exe vexga4m1et4.exe etc"
X Service Pack DLL Runtime spdll32.exe"Added by a variant of the RBOT WORM!"
X Service PAck SFVP [worm filename].exe"Added by a variant of the RBOT WORM! The filename is 4 random characters"
X Service Process SVCHOST.EXE"Added by the DARKER WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder"
X Service Process winset.exe"Added by a variant of the SPYBOT WORM!"
X Service Process service.exe"Added by the DCMBOT-C TROJAN!"
X Service Process smss.exe"Added by the DCMBOT-E TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""config"" subfolder"
X Service Process svchost.exe"Added by the DCMBOT-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""config"" subfolder"
X Service Registry NT Save jdbgmgrnt.exe"Added by the BANCOS-CG TROJAN!"
X Service Registry NT Save taskmgrnt.exe"Added by the BANCOS-BY TROJAN!"
X Service Registry NT Save regeditnt.exe"Added by the BANCOS-BM TROJAN!"
X Service Scheduler scheduler.exe"Added by the AGOBOT-PH WORM!"
X Service System kernels32.exe"Added by the BANCOS-DA TROJAN!"
X Service System windowsXP.exe"Added by the BANCOS-EL TROJAN!"
X Service System kgbfsm344.exe"Added by the BANCOS-FS TROJAN!"
X Service System wernell87.exe"Added by the BANCOS-FJ TROJAN!"
X service updaer qualityz.exe"Added by an unidentified VIRUS WORM or TROJAN! - probably a SPYBOT variant"
X Service Update Client svcupdcli.exe"Added by an unidentified WORM or TROJAN! See here"
X Service.exe Service.exe"""servedby.advertising"" popup generator"
X Service2 Service2.exeIdentified as a variant of the Win32.Iroffer malware. Located in %Windir%\Drivers\Intel
X service32 service32.exe"Added by the AGOBOT-ST WORM!"
X service32.exe [path to trojan]"Added by the DLOADR-AYX TROJAN!"
X Service SERVICES.EXE"Added by the BRONTOK-BH WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
U ServiceConfig ispbeg.exeComcast Transition Wizard. On June 30th 2003 it will migrate E-mail and web pages from AT&T Broadband Internet to Comcast High-Speed Internet. Until then it will run at startup and then terminate - hence the U recommendation
X serviceconnect serviceconnect.exe"Added by the AGOBOT.AIR WORM!"
X Servicee services.exe"Detected by Trend Micro as the AGENT.DEI TROJAN! See here. Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder"
X ServiceHost svch0st.exe"Detected by Kaspersky as the VB.HE VIRUS! See here"
Y ServiceLayer ServiceLayer.exeNokia Connectivity Library support task that is needed by NCLTRAY and by the Nokia Connection Manager for either to work properly
X servicemng service.exe"Added by the TAME-C WORM!"
X Servicer servcr.exe"Added by the SDBOT.BAH TROJAN!"
X Servicerepclient1 SERVICES.EXE"Added by the BRONTOK-BT WORM and variants! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
X services start.bat"Added by the ZCREW TROJAN!"
X Services [path to trojan]"Added by the METEORSHELL TROJAN!"
X Services back32.exe ...service.exeAdded by an unidentified VIRUS WORM or TROJAN! Back32.exe is the baddie whose purpose is to HIDE the MIRC32 server in service.exe
X Services services.exe"Added by a number of VIRUSES WORMS and TROJANS! Note - this is not the legitimate services.exe process which should NOT appear in Msconfig/Startup!"
X Services winread.exeAdded by an unidentified VIRUS WORM or TROJAN!
X Services windns.exe"Added by a variant of the RBOT WORM!"
X Services mshost.exe"Added by the LANFILT-J TROJAN!"
X services Svchosts.exe"Added by the SDBOT-N TROJAN!"
X Services csrss.exe"Added by a variant of the RANKY.U TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
X Services scks32.exe"Added by a Proxy Trojan variant"
X Services sockys32.exeAdded by the RANKY.L TROJAN!
X Services sys.exe"Added by a Proxy Trojan variant"
X services windows32.exe"Added by the FLYVB-C WORM!"
X services socks.exeAdded by the WIN32.SMALL.N TROJAN!
X Services services.exe"Added by the ZINCITE.A TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder"
X Services [path to trojan]"Added by the RANCK-DB TROJAN!"
X Services iexplore.exe"Added by the MOGI WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
X Services svchost.exe"Added by the REPER-B WORM! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
X Services sysamp.exe"Added by a variant of the SDBOT WORM!"
X Services prosys32.exeAdded by an unidentified WORM or TROJAN!
X Services iexplorer.exeAdded by an unidentified WORM or TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
X Services iexploler.exe"Added by the RANCK-LT TROJAN!"
X Services iexpolere.exe"Added by the RANCK.LU TROJAN!"
X services sample.exe"Added by a variant of the RANKY TROJAN!"
X Services Administrator localsvc.exe"Added by the DLOADER-NY TROJAN!"
X Services Administrator netsvc.exe"Added by the DLOADER-NY TROJAN!"
X Services Administrator spoolsvc.exe"Added by the DLOADER-NY TROJAN!"
X Services Administrator svcadmin.exe"Added by the DLOADER-NY TROJAN!"
X Services Administrator svcman.exe"Added by the DLOADER-NY TROJAN!"
X Services Administrator svcrun.exe"Added by the DLOADER-NY TROJAN!"
X Services Administrator tcpsvc.exe"Added by the DLOADER-NY TROJAN!"
X Services Administrator websvc.exe"Added by the DLOADER-NY TROJAN!"
X Services Controller lsassa.exeAdded by the CIADOOR.122 VIRUS!
X Services Controller services.exe"Added by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder"
X Services DLL Loader srvdll.exe"Detected by Trend Micro as the IRCBOT.AYN BACKDOOR! See here"
X Services Host Scchost.exe"Added by the DONK WORM!"
X Services Host svchost32.exe"Added by the AGOBOT-TG WORM!"
X Services Logon services.exe"Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Templates"
X Services Management Clients servc.exe"Added by the RIZO.A TROJAN!"
X Services Managements servcs.exe"Added by the RBOT-GUC WORM!"
X Services Manager svsmanager.exe"Added by an unidentified TROJAN! See here"
X Services Manager! svmanager.exe"Detected by Trend Micro as the IRCBOT.ATZ TROJAN! See here"
X Services Managers svcmanager.exe"Added by a variant of the IRCBOT TROJAN! See here"
X Services Process services.exe"Spyware - detected by Kaspersky as the SMALL.X TROJAN! Note - this is not the legitimate services.exe process which should not appear in Msconfig/Startup!"
X Services Process smss.exe"Added by the SMALL-EK TROJAN! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a ""config"" subfolder"
X Services Start2 odcwinst.exe"Added by the PYSKE-D WORM!"
X Services Startup services.exe"Added by the CROWT.A WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %ProgramFiles%\Common Files"
X Services Startup svhost33.exe"Added by a variant of the RBOT WORM!"
X Services.dll smss.exe"Added by the SOBER-L WORM! Note - this is not the legitimate smss.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in a msagentsystem subfolder of the Winnt or Windows folder"
X Services.EXE services.exe"Added by the KAZPING WORM! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder"
X services.exe Services.exe"Added by the CIADOOR-F TROJAN! Note - this is not the legitimate services.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Windows or Winnt folder"
X services.exe servicess.exe"Added by the MSNSPY-B TROJAN!"
X Services004 [worm filename]"Added by the BUGBROS WORM!"
X services32 mc-110-12-0000079.exeAdded by the TrojanDownloader.Agent.rv TROJAN!
X services32 mc-58-12-0000120.exe"""Shorty"" adware - also detected as the AGENT.FD TROJAN!"
X services32 mc-58-12-0000140.exe"""Shorty"" adware - also detected as the AGENT.FD TROJAN!"
X Services32 Startup win32dll.exe"Added by the SDBOT-XO WORM!"
X ServicesAdministrator SERVICES.EXE"Added by the PUNYA-B WORM! Note - this is not the legitimate services.exe process which should not appear in Msconfig/Startup!"
X Servicesara services.exe"Added by the BRONTOK-BS WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
X ServicesLoad lsass.exe"Added by the DEARIS-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is located in the Winnt or Windows folder"
X ServicesLog ccapp32.exe"Added by the RBOT-AMX WORM!"
U ServicesNotify ServicesNotify.exe"Defender Pro Antispy"
X servicestub.exe servicestub.exe"Detected by Trend Micro as the RBOT.CN TROJAN! See here"
X Servicewin Hide32.exe"Added by the MSNVB-D WORM!"
X Servicing hostd.exe"Added by the SDBOT.BUI WORM!"
X Servicio Local svhost.exe"Added by the SPYBOT.BGX WORM!"
X Servicos AdobeLanc.exe"Added by the BANKER-EHR TROJAN!"
X Servicos System.exe"Added by the BANCOS-BCM TROJAN!"
X servics servics.exe"Added by the SINGU-J TROJAN!"
X SERVlCE SERVlCE.EXE"Added by the AGOBOT-UB WORM!"
? ServUTrayIcon ServUTray.exe"System Tray icon for Serv-U FTP server. Is it required?"
X SES Service sesvc.exe"Added by the SDBOT-CZU WORM!"
U Session Client sescli.exe"SurfSpy keystroke logger/monitoring program - remove unless you installed it yourself!"
X Session Manager Subsystem smssa.exe"Added by the RBOT-AGS WORM!"
X SESync sed.exe"DownloadWare adware"
? SetCacheMode rundll32.exe ptipbmf.dll SetWriteCacheModeInstalled with the miniport drivers for Promise hard drive controllers in both RAID and non-RAID installations. May be necessary in order to maintain preferences applied to the RAID array connected to the Promise controller
? SetDefaultMIDI MIDIDef.exe"Related to a Soundblaster Audigy soundcards. What does it do and is it required?"
Y SetDefaultPrinter cloaker.exeUsed by HP and Compaq computers to hide the windows of programs passed as arguments to it
N setdefprt setdefprt.exeUsed to set a Brother MFC printer/copier/scanner as the default printer after installation
N SetDefPrt BrStDvPt.exeUsed to set a Brother MFC printer/copier/scanner as the default printer after installation
U SetecCertUtil Certutil.exeSetec Web and Email Security. Setec PKI smart card software. The PKI technology enables secure and reliable user identification in services offered through Internet mobile handsets and digital TV
X setFTPBack createsw.exe"Added by the FTP_BMAIL TROJAN!"
N SetHook SetHook.exe"Fellowes Neato CD label design software. ""Launch NEATO's MediaFACE II label making software directly from the productname toolbar"""
N SETI@home SETI@home.exeSETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data
N seticlient SETI@home.exeSETI@home is a scientific experiment that uses Internet-connected computers in the Search for Extraterrestrial Intelligence (SETI). You can participate by running a free program that downloads and analyzes radio telescope data
N SetIcon SetIcon.exeInstalled by a 6-in-1 (4 Media Card slots a floppy drive and a USB connection) device. Constantly updates the icons for the four Media Card slots that it has and is a resource hog
N SetiQueue Setiqu~1.exe"Provides work unit buffering for Seti@Home clients - see here for more details"
N SetiSpy SetiSpy.exe"SETI Spy is a little program to ""spy"" on the progress and performance of the SETI@home client. Called a ""spy"" because it is unobtrusive as possible"
X SetPoint SetPoint.exe"Added by the RBOT-BWI WORM! Note - this is not the valid Logitech Setpoint mouse and keyboard entry that uses the same filename and is located in the LogitechSetpoint sub-folder of Program Files. This file is located in the System (9x/Me) or System32 (NT/2K/XP/Vista) folder"
U SetPoint Setpoint.exeLogitech SetPoint Event Manager for their range of mice and keyboards. Required if you want to use the advanced features of these devices and is located in the LogitechSetpoint sub-folder of Program Files
X SETPOINT Logitech Inc KHALMNP.exe"Added by the RBOT-AAX WORM!"
U SetRefresh SetRefresh.exeVideo refresh rate utility found on some HP and Compaq PCs. Recommended for CRTs but not LCDs
X Setting sysweb.exe"Added by the SDBOT.GEN TROJAN!"
N setup hphprld.exe ....setup.exeHP DeskJet Setup - printers function normally without it
X Setup experation svchost.exe"Added by the TOFGER-AW TROJAN! Note - this is not the legitimate svchost.exe process which is always located in the System (9x/Me) or System32 (NT/2K/XP) folder and should not normally figure in Msconfig/Startup! This file is found in the Winnt or Windows folder"
X setupa runt32.exe"Added by the QQPASS-K TROJAN!"
X setupdata rnll32.exe"Added by the QQPASS-AC TROJAN!"
N SetupICWDesktop icwconn1.exeAppears to be the "Internet Connection Wizard" from Internet Explorer being set-up as a desktop shortcut. Appears under the RunOnce registry key but is available under Start -> Programs -> Accessories -> Communication (or similar) anyway
X setupuser regedit.exe setupuser.log"Regfile in disguise - another CoolWebSearch parasite variant"
? setuzp setuzp.exe"??"
X SetVrc setvrc.exe"Added by the HUNTOCX WORM!"
X Sevice winconfig.exe"Added by the GIP.113.B1 TROJAN!"
X Sex Teris st01b.exe"Added by the REPAD WORM!"
X Sexnow Sexnow.exe"Added by the SENOW-B premium rate adult content dialler"
X Sexy_Blondes Sexy_Blondes.exe"Added by the Sexy DIALER! Related also to Hot Tarts DIALER!"
X Sexy_sg Sexy_sg.exePremium rate adult content dialler
X sf sf.exe"SurfEnhance adware component"
N SFIGUI SFIGUI.EXE"Sonic Focus - ""enhances music movie and game sound by analyzing compressed audio streams in realtime then restoring and enriching audio back to its original performance qualities"""
X sfita sfita.exe"Added by the FAVADD-H TROJAN! Also known as SurfEnhance adware"
X SfKg6w rayiou.exe"Added by the AGENT.BUO WORM!"
X SfKg6wIP [random filename]Identified as a variant of the TrojanDownloader.Matcash malware
X SfKg6wIPu [random filename]Identified as a variant of the TrojanDownloader.Matcash malware
N SFP vzSFPWin.EXEVerizon Online Support Center - prompts for online updates
U sfpc sfpc.exe"Spy4PC surveillance software. Uninstall this software unless you put it there yourself"
X SFtrb Service cftrb32.exe"Added by the SOBIG.D WORM!"
U SfWinStartInfo sfWinStartupInfo.exeSFIRM32 Online Banking software
U Sgecrypt Sgecrypt.exe"SafeGuard Easy - ""provides total company-wide protection for sensitive information on laptops and workstations. Boot protection pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"""
U Sgeecview Ecview.exe"SafeGuard Easy - ""provides total company-wide protection for sensitive information on laptops and workstations. Boot protection pre-boot user authentication and hard disk encryption using powerful algorithms guarantee against unauthorized access and hacker attacks"""
U sginst sginst.exe"eAcceleration Stop-Sign security software related. Previously not recommended see here"
? SGTBox SGTBox.exe"Canon scanner driver. Is it required?"
U sgtray sgtray.exe"StorageGuard from Veritas. Free utility that integrates with Backup MyPC (formerly Backup Exec Desktop) Simple Backup and MS Backup. Provides system tray access and background monitoring - warning you of files that haven't recently been backed up. Required unless you backup manually on a regular basis or have scheduled backups"
Y Shadow Shadow.exe"""NTI Shadow 3 is an award-winning easy-to-use backup application that automatically protects your photo music video and various data files. It makes data restoration as easy as dragging and dropping files from one place to another"""
U ShadowUser Pro Edition ShadowUser.exe"""StorageCraft? ShadowUser? provides easy to use desktop security and protection for Windows operating systems. ShadowUser is the best way to prevent unwanted changes to PCs and laptops"""

DISCLAIMER: It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. I will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.

Powered By Pac's Startup list